Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
AI Summary
A malicious npm package named 'tw-pkgprobe-7731' was uploaded to the npm registry by a now-defunct account 'twdepprobe7731', masquerading as an authorized Twilio bug-bounty probe. The package targets Twilio developers by checking for specific environment conditions and, if met, exfiltrates environment variables, system configurations, and Twilio credentials such as ACCOUNT_SID and AUTH_TOKEN. Later versions attempted to inject malicious npm packages and perform OSINT gathering on Twilio-related infrastructure, though the final versions reverted to benign behavior, suggesting possible testing or evasion. The package violates Twilio's HackerOne security research guidelines and shows no obfuscation, indicating a low sophistication threat actor.
AI-extracted · verify before operational use